Security Specialist Resume Profile
CYBERSECURITY MANAGEMENT
Senior Level with 5 key ingredients: Business Management, Business Development, Systems Security, and Security Compliance experience as well as IT Security Architecture Infrastructure focusing on Security Management for National and International Operations within the Financial, Health, Educational, Governmental, Manufacturer, and Energy Industries. Adept at cultivating partnerships and building lasting relationships across all business sectors with progressive experience in directing complex projects, developing strategies and leading teams to further enhance overall operations.
CORE COMPETENCIES
15 years of Management and hands - on experience in:
Cyber Security
Risk Assessment Risk Management
Information Assurance Analyst
Cyber Crime Law Investigation
Security Project Management
Risk Analysis Incident Response
Access Control Systems
Network Telecommunications Security
Application Security
Business Continuity Disaster Recovery
Encryption Cryptography
Security Architecture System Model
Security Implementation
Security Standard Best Practices
Wireless, Mobile Voice IP
Security Policies Methodologies
Social Engineering
Vulnerability Assessment Penetration Testing
Operation Physical Security
Security Training Awareness
Regulatory Compliance
Customized Reports
PROFESSIONAL EXPERIENCE
confidential
Sr. Security Specialist
Responsibilities: Security program development, SIEM deployment, plugin creation, correlation creation, directive creation, alerts, alarms, connecting data sources, analyst training and general system engineering, social engineering, compliance auditing, vulnerability management, policy creation, reporting to stakeholders, awareness training, appliance evaluation/recommendations and PCI auditing.
confidential
Sr. Security Engineer, and Project Manager
Responsibilities: Managed numerous large client IT security projects with 100's of IT Staff and 1000's of Users.
- The primary focus of the company is IT related security consulting and enterprise security auditing with significant expertise in regulatory compliance in Financial, Healthcare, Educational, Manufacture, Energy, Retail Industries as well as and Government Agencies. Lead role responsibilities include successfully managing and supervising regulatory compliance with the latest industry standards and information security systems best practices for key clients, including: Banks, Credit Unions, Government Agencies, Healthcare Systems and Nuclear Systems among others. Effectively reduced security exposures and strengthen overall organizational effectiveness by strategically designing secure networks and managing implementation of numerous security programs. Adeptly perform ISO 17799 audit and ISO27001 framework, including: policy, access controls, network security, platform security, app security, compliance and incident response. Concisely write thousands of information security scopes of work SOW for clients and government RFPs. Consistently provide coordination support for investigations and extensive training in DIACAP and Information Assurance for Department of Defense clients.
- Over the last five years, I have managed a Security Operations Center for Northrop Grumman. In that position, I managed and performed the duties of the engineering, infrastructure, operations and incident response teams. I have vast experience with commercial grade Cisco routers, switches, FWSM, Juniper firewalls, BlueCoat, IBM ISS IDS, RSA, TrustWave SIEM, eEye Iris Retina systems, FireEye malware systems, IronPort, a number of anti-virus systems, QualysGuard, EnCase and many other security tools.
confidential
Systems Engineer
- Responsibilities: e-commerce applications development, consulting with local businesses, web developing, graphic optimization, systems administration, and taught A certification course for Youth Technology Corp. Maintaining on-line classroom environment, web development, coordinating services.
- The primary focus of the position included full system lifecycle planning, LAN/WAN network architecture for 7 colleges via distance learning, exchange server creation and maintenance, PBX management, network architecture, implement security measures, satellite communications and encryption, board representative at 23, controlled bids and outside consultants, policy and procedure creation and implementation, maintained the first online governors school and technical triage when needed 24/7.
SELECTED ACHIEVEMENTS
- Managed numerous large client IT security projects.
- Completed over 1,500 Security Assessments, Audits, and PCI/FISMA/DIACAP/HIPAA Compliance. Managed over 40 IT Security Engagements in 5 States.
- Managed a team of Cyber Security Consultants in secure network design, systems analysis/development and full life cycle project management.
- Assisted developing a new Log and monitoring technology saving the client millions of dollars per year in 24/7 monitoring of 82 State and Federal Agencies.
- Managed enrollment/implementation of IBM AS/400 for financial Industries. Completed HP IDM/SIEM implementation projects.
- Managed FISMA Compliance for Federal National Health Information Network in prototype phase.
- Trained hundreds of client's IT staff in Information Security and Awareness.
TECHNICAL AREAS OF EXPERTISE
- Security Audits : GLBA, HIPAA, SOX, FISMA, DIACAP, FERPA, NRC, PCI Compliance, SAS 70/94, ISO, FIPS 200.201.202, COBIT, NSA IAM, NIST Methodology, and FFIEC IT Guidelines.
- Tools Networking: Alienvault, Trustwave, Intellitactics, ArcSight, Qualys, ISS Proventia, eEye Retina, SAINT, Rapid7, Nesses, OpenVAS, OpenDLP, BlueCoat, IronPort, Backtrack, Ubuntu, Red Hat, Debian, Helix, FireEye, Symantec Endpoint, McAfee AV, Juniper, Cisco ASA, ACS, Snort, Nmap, Python, IDS/IPS, OpenView, Tivoli, SSO, VPN, SSH, SSL, PGP, AKT, PKI, Identity Management, Access Management, and Content Management.
- Platforms: Windows, Linux, UNIX, Mac OS X, and AS/400.
